Yealink Meeting Server unauthorized Vulnerability
CVE Dictionary Entry:
DATE PUBLISHED: 2023-11-24
DATE UPDATED: 2024-04-01
Vulnerability Summary
Due to unauthorized access vulnerabilities in certain interfaces, attackers can directly access the interface and obtain all user information of the enterprise, including passwords (encrypted), only knowing the enterprise ID.
Product Affected
Product Family and Model | Affected | Fixed |
Yealink Meeting Server | < V26.0.0.67 | V26.0.0.67 |
Vulnerability Solution
Yealink has released a software update to address the vulnerabilities in versions earlier than 26.0.0.67. Please update promptly.
Resolution Measures
Yealink recommends all customers to upgrade to the latest version.
Acknowledgments
We sincerely thank the Positive Technologies team for their professional support in addressing this security issue.
Contact
Any customer using an affected system who is concerned about this vulnerability within their deployment should contact Yealink Technical Support by visiting: https://support.yealink.com/en/portal/home for the latest information.
You might also find value in the high-level security guidance and security news located at: https://support.yealink.com/en/portal/home.